Solved

Why does loopback mode trump GPPE drive maps but not GPO user logon script?

Posted on 2013-06-17
1
1,102 Views
Last Modified: 2013-06-18
I recently migrated my users to a new GPO structure, taking advantage of numerous Group Policy Preferences. I’ve stumbled on to an issue where users’ drive mappings are not being made when they log into a conference room computer.

These conference room computers have loopback enabled (“Replace”) so I can lock several, albeit minor, settings down. The drive mappings are done via User GPPE > Windows Settings > Drive Maps. In the old days, I did it with a GPO user logon script (which worked). The GPPE drive maps do not work.

If I change the loopback mode to “merge”, it will work, but then I lose my ability to lock stuff down.

Anyone have an explanation or advice how to get around this?
0
Comment
Question by:RhoSysAdmin
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
1 Comment
 
LVL 84

Accepted Solution

by:
oBdA earned 500 total points
ID: 39255324
To start with: you don't lose the ability to "lock stuff down" with Loopback processing in Merge mode.
All that Loopback mode does is tell the OS to apply user configuration GPOs based on the OU where the computer account is.
In "Merge" mode, the user configuration GPOs will be applied based on the user object's location in AD first, then the user configuration GPOs based on the computer object's location in AD (so that with concurrent policies, the one applied via Loopback will always win).
In "Replace" mode, any user configuration GPO based on the user object's location in AD will be skipped altogether, and only the ones linked to the computer object's location will be applied.
So you can either use "Merge" mode, making use of the Loopback's higher priority to lock down whatever was allowed in the default GPOs, or you can use "Replace" mode to log the users on with a clean slate, put all the drive mapping GPPs into their own dedicated GPO, and link the drive mapping GPO not only to the user OU, but to the conference room OU as well (or duplicate the GPPs, but if you need the same drive mappings, then that's not really the best solution).
Loopback processing of Group Policy
http://support.microsoft.com/kb/231287
0

Featured Post

Salesforce Has Never Been Easier

Improve and reinforce salesforce training & adoption using WalkMe's digital adoption platform. Start saving on costly employee training by creating fast intuitive Walk-Thrus for Salesforce. Claim your Free Account Now

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
The Windows functions GetTickCount and timeGetTime retrieve the number of milliseconds since the system was started. However, the value is stored in a DWORD, which means that it wraps around to zero every 49.7 days. This article shows how to solve t…
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum editing capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question